Privacy Policy
Nikahsatu Service Optimizer · Last updated 7 July 2026 · Draft — prepared with reference to the Personal Data Protection Act 2010 (Malaysia)
1. Data user
Nikahsatu ([SSM_REG_NO]), [ADDRESS], Malaysia. Data protection contact: [DPO_EMAIL].
2. What we collect
- Account data: name, email, password hash (or Google sign-in), organization name.
- WhatsApp group data (when your organization connects a number): message text, sender names/phone numbers/WhatsApp identifiers (including privacy LIDs), timestamps, and group metadata for the groups you choose to track.
- Derived data: response-time metrics and AI-generated analysis (category, sentiment, satisfaction estimate, summaries).
- Technical data: logs necessary for security and reliability (IP, timestamps, event metadata).
3. Purposes
We process the above to provide team-performance analytics to the organization that connected the WhatsApp number, to operate and secure the Service, and to comply with law. We do not sell personal data or use your conversations to train AI models.
4. The organization's duty (group participants)
The organization connecting a WhatsApp number is the primary data user for its group conversations. It must inform group participants (staff and customers) that conversations are analyzed for service-quality purposes and secure any consent PDPA requires. We process that data on the organization's instructions.
5. Processors & transfers
- Supabase (database/auth) — hosted in Singapore (ap-southeast-1).
- AI providers — conversation transcripts are sent for analysis to the provider whose API key the organization supplies (e.g. DeepSeek or Anthropic), under that provider's terms. The organization chooses its provider.
- Hosting — [VPS_PROVIDER/REGION].
Where data is transferred outside Malaysia we take reasonable steps to ensure it is protected to standards comparable to the PDPA.
6. Retention
Account data: for the life of the account. Message and analytics data: while the organization remains active, or until the organization deletes it. After account termination we delete organization data within 30 days, except records required by law. Backups roll off within [BACKUP_WINDOW] days.
7. Security
Data is encrypted in transit (TLS) and at rest (provider disk encryption). Access is isolated per organization (row-level security), API keys are stored server-side only, and administrative access is restricted and logged.
8. Your rights (PDPA)
You may request access to or correction of your personal data, withdraw consent, or complain about processing by contacting [DPO_EMAIL]. If you are a customer whose messages appear in a tracked group, we will route your request to the organization concerned and assist as required. We respond within 21 days as PDPA prescribes.
9. Cookies
We use only session cookies necessary for sign-in (Supabase auth) and a preference cookie for the light/dark theme. No advertising trackers.
10. Changes
We will notify account owners of material changes via the dashboard or email at least 14 days before they take effect.